Legal
Privacy Policy
Last updated August 23, 2026
What we collect
When you create an account, we collect your email address. If you connect Strava, Wahoo, and/or Hammerhead, we receive your athlete/user ID and activity data (rides, runs, distance, elevation, heart rate, power, and similar metrics) from that service's API, with your authorization. If you connect RunGap instead, the same categories of activity data arrive differently: RunGap is a separate app you configure yourself to send us a workout file whenever you sync one, using a webhook address and passkey we generate for your account, see "Who we share it with" below for how that differs from an API connection. If you connect more than one and the same real-world workout is reported by each, we keep only one copy of it rather than storing it twice. We also store the goals and training plans you create within Training Signals.
Your Functional Threshold Power (FTP) is either a value you enter yourself in Settings or an estimate we compute from your own synced power-meter rides. We do not read it from your Strava athlete profile. You can enter your body weight directly in Settings; it is stored in kilograms internally and used only for performance calculations (watts per kilogram).
If you connect a recovery device or service (Oura, WHOOP, Fitbit, or Apple Health via the iOS app) we receive and store daily recovery summaries with your authorization: readiness/recovery scores, sleep scores and sleep duration, overnight heart-rate variability (HRV), and resting heart rate. We store daily summaries only, not raw sensor streams. For WHOOP and Fitbit we also import the workouts you record, sport, start and end time, strain (WHOOP), average and maximum heart rate, and distance where available, so your training history works even if that device is your only tracker. Apple Health data is read on your device by our iOS app and sent to us as those same daily summaries; you control access in iOS Settings > Privacy & Security > Health, and disconnecting a recovery service in Connections deletes its stored recovery data (and, for WHOOP and Fitbit, its imported workouts) from our systems.
Fitbit and Pixel Watch data reaches us through Google's Health API, authorized with the Google account your Fitbit app uses. We request read-only access to your activity and exercise sessions, sleep, and heart-rate metrics, plus your Google Health profile identifier so your data can be matched to your connection. The use of information received from the Google Health API will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements: we use this data only to provide the coaching features you see in the app, we never sell it, never use it for advertising, and never let a human read it except as that policy allows.
If you use the Athlete Memory or AI coaching features, we store the profile notes you or your AI coach write (injury history, equipment, preferences, training load feedback, and other notes) along with an append-only audit log recording every change (who made it and when). You can view and edit this data on your Profile page at any time.
How we use it
We use this data to calculate training load, fitness, and recovery metrics (including watts per kilogram when both FTP and body weight are set), generate training plans, and provide coaching advice. Some coaching messages are generated or rewritten by Anthropic's Claude API for eligible accounts. Anthropic acts as our subprocessor. It processes this data solely to return coaching text to you, on our behalf and under our contract, not for its own purposes. We send only derived training context (goals, fitness/fatigue metrics, FTP, power zones, body weight, athlete memory notes, daily recovery summaries such as readiness scores, sleep duration, HRV, and resting heart rate, and similar summaries). We never send your raw Strava, Wahoo, or Hammerhead activity feed, your GPS coordinates or route maps, or your name or email address. When your coach writes about one specific session, the title of that session goes with it, so it can tell you which ride it means. We do not use this data to train, fine-tune, or build AI models, and, under Anthropic's commercial terms, data submitted through our API integration is not used to train their models. We do not currently build searchable embeddings or vector indexes from your data; if that changes, we will update this policy and describe what is indexed and how it is deleted.
None of that happens until you say so. Before any of your training reaches Anthropic we show you what is sent, name who receives it, and ask. Saying no costs you the written coaching and nothing else: your plan, your sync, your charts and your records all keep working. You can change your answer either way at any time under "How your data is used" in Settings. Turning it off stops the next send rather than recalling what has already gone, and while it is off we generate no coaching text at all.
Who we share it with
We rely on a small set of subprocessors that handle data on our behalf under contract: Supabase to store account and training data, Anthropic to generate some coaching messages (see above), and Vercel to host the application. We source activity data from Strava, Wahoo, and/or Hammerhead under your authorization, and Fitbit data from Google's Health API under your Google authorization, which you can revoke at any time in that service's own account settings (for Fitbit, under your Google account's third-party access settings), or by disconnecting it from our Connections page. If you connect RunGap, activity data arrives because you configured RunGap yourself to send it to a webhook address we generate for your account, RunGap is not a subprocessor we hold a data-sharing agreement with, and we have no way to reach into RunGap or revoke its access from our side; that's controlled entirely within RunGap's own settings on your device. We do not sell your data, and we do not disclose your Strava, Wahoo, Hammerhead, or RunGap-sourced data to any party other than these subprocessors, you, and anyone you deliberately send a share card to.
That last one is entirely your choice, and worth spelling out. You can export a single session as a share card. If you then pick somewhere to post it, we create a long, unguessable web address for that one card, so the site you are posting to can fetch it and show the picture in your post. Anyone holding that address can open it without signing in. It shows that card alone, the session's headline figures and a short summary, and never anything else from your account. No link exists until you pick a destination, and you can take one down at any time from the same panel you created it in. Taking it down stops us serving the card, but it cannot remove a copy a social network already fetched and cached.
How we protect it
Everything that moves between your device and our servers, and between our servers and the services you connect, travels over encrypted connections (TLS). At rest, your data lives in Supabase with disk-level encryption, and access is governed by row-level security rules: your rows are readable by your account, not anyone else's.
The credentials that make your connections work get a further layer. When you authorize Strava, Wahoo, Hammerhead, WHOOP, Oura, or Fitbit, that service hands us access tokens rather than your password (we never see the password), and we encrypt those tokens with AES-256-GCM before storing them, using a key held outside the database. A copy of the database alone is not enough to read them.
No setup makes a breach impossible, so the practice that backs all of this is holding less in the first place: daily summaries rather than raw sensor streams, derived training context rather than full activity feeds, and everything we do hold deletable by you (see "Your data, your control" below).
Cookies, on-device storage, and analytics
We use a session cookie/local storage entry to keep you signed in -- this is required for the app to function and isn't optional. We use Vercel Web Analytics for aggregate traffic insights, which does not use cookies or collect personally identifiable information.
The app also keeps a copy of recent training data on the device you are using, so a screen can show you something the moment you open it instead of a spinner, and so it still has something to show when you have no connection. It holds what the screen you last visited was showing: your recent sessions, your current plan, the coach's notes and its recent messages. It is replaced each time the app reaches us, and it is kept until you sign out, delete your data, or clear it in Settings, rather than expiring on a timer. That is deliberate: a device that has been away from a network for a week should show you last week's plan and tell you it is last week's, not an empty screen. It stays on your device, is never sent anywhere, and we cannot read it.
Offline mode stores the app's own screens on the device as well, so it opens and works when you have no connection. It holds none of your training data, only the app itself. In the iOS app it is on to begin with, because an app that stops working when you ride out of signal is the problem it exists to solve; in a web browser it is off unless you switch it on. Either way it is a per-device setting rather than an account one, Settings shows how much is stored with a button to clear it, and switching it off deletes what it stored.
The short-lived copy of your training described above is deleted from the device when you sign out and when you delete your data. Because it lives on the device rather than in your account, signing out on a shared or borrowed device is what removes it there.
We also keep our own basic traffic counts, without cookies: the page path, the country/region/city your network resolves to, the host that linked you to us (the site name only -- never the full address, so we never see what you searched for), and, on blog posts, whether a reader scrolled far enough and stayed long enough to have read the piece. Each of these is stored against a one-way visitor code derived from your IP address and the current date -- we never store the IP itself, and because the code changes daily it stops being linkable to you tomorrow.
Your data, your control
You can disconnect Strava, Wahoo, Hammerhead, and/or RunGap from the Connections page, or delete all of your data at any time from Settings. For Strava, Wahoo, and Hammerhead, disconnecting revokes our access on that service's side and deletes the activities and FTP estimates synced from it. Disconnecting Fitbit does the same through Google: we revoke our own authorization with Google and delete the recovery data and imported workouts that came through it. RunGap has no such access to revoke. We delete the activities and connection on our side, but you should also remove the webhook from RunGap's own settings so it stops trying to send workouts to a URL that no longer accepts them. Either way, this keeps your goals, training plans, and coaching history. Deleting your data removes those too, along with everything your coach worked out about you: its notes, what it remembers about your body and your training, and your whole conversation history. It also empties your profile of what you told us about yourself, including your FTP, your weight and weight history, your threshold pace, the sports you do and the days you can train, and it removes every connected source along with the credentials that let one push data to us. You are signed out when it finishes. Your login still works, and signing back in starts you over from setup. Your coach also keeps a change history, so you can see when it updated something it knows about you. The wording of each change is kept for 30 days and then dropped, leaving only the record that a change happened. Three things are kept on purpose. Billing records, because deleting them would strip the subscription you are still paying for and erase our record of a purchase you might later dispute. A small amount of cost-accounting and abuse-prevention logging, which holds identifiers and counts, never anything you wrote or anything the coach concluded. And the record that you accepted these terms, which is a version number and a date, kept because it exists to be produced later. Synced activity data from Strava, Wahoo, or Hammerhead is also automatically purged after 365 days even if you stay connected, consistent with Strava's API Agreement. RunGap-sourced activity data is not subject to this automatic purge, since RunGap can be used to import years of historical training history in one go and Strava's API Agreement doesn't apply to it. It's retained until you disconnect RunGap or delete your data.
Contact
Questions about this policy? Contact us at support@trainingsignals.cc.